← Back to all sparks
F

Froxlor

DEVOPS
Velocity5.0

Server administration and hosting control panel

Froxlor's bugfix tags ship with nothing but a compare link.

hosting-panelopen-sourcesecurity-fixesempty-release-notes
Current state
Froxlor is an open-source server administration panel. 2.3.13 is tagged a bugfix release, but its release note contains only a link comparing it to 2.3.12 — no described change. The substantive recent work was the 2.3.11 security release, which fixed a 2FA bypass, DKIM key exposure and acme.sh argument injection.
Where it's heading
The releases that carry real notes are the security ones, and they have been arriving steadily: CSRF tokens on AJAX actions in 2.3.8, a redirect regression reverted in 2.3.9, then the three-issue fix in 2.3.11. The bugfix tags between them publish empty bodies, so the feed alternates between detailed security disclosure and silence. Direction has to be read from the security releases alone.
Prediction
No direction can be read from this release, because the body describes nothing; on the recent pattern the next informative entry will be another security release.

Recent moves

  1. 19d ago

    froxlor bugfix release 2.3.13

    Tagged a bugfix release, but the body is only a compare link to 2.3.12, so what changed is not visible from the feed. The same shape as 2.3.12 and 2.3.10 before it.

    View source ↗
  2. 24d ago

    Froxlor bugfix release 2.3.12

    Another bugfix tag published with a bare compare link and no described change.

    View source ↗
  3. 24d ago

    2FA bypass, DKIM key exposure and acme.sh argument injection all fixed

    The substantive recent release: a 2FA bypass, DKIM key exposure and acme.sh argument injection all fixed. This is where Froxlor's feed actually documents itself.

    View source ↗
  4. 3mo ago

    froxlor security release 2.3.10

    A security-tagged release whose body is a compare link only, giving no detail on what was fixed.

    View source ↗
  5. 3mo ago

    2.3.9 reverts an HTTP-to-HTTPS redirect regression from 2.3.8

    Reverts an HTTP-to-HTTPS redirect regression introduced in 2.3.8 — a correction to the prior release rather than new work.

    View source ↗
  6. 3mo ago

    2.3.8 adds CSRF tokens to AJAX actions and filters API responses

    CSRF tokens added to AJAX actions and API responses filtered — hardening of the panel's request surface.

    View source ↗